This deck exists because of a real detection trick: interviewers discovered that asking a remote candidate to say something insulting about Kim Jong Un sometimes ends the call instantly. That is funny. The reason it works is not. Here is what is actually known, what the trick is and isn't good for, and what to do instead.
What the scheme actually is
North Korea runs a large, state-directed programme that places IT workers into remote jobs at Western companies under false identities. The salaries are funnelled back to the regime, which is the point: it is a sanctions-evasion revenue operation, not primarily an espionage one. Google's Mandiant tracks the activity as UNC5267; Microsoft tracks an overlapping set as Jasper Sleet.
The mechanics are consistent across cases. A worker applies using a stolen or synthetic US identity, often with an AI-retouched profile photo. If hired, they ask for the company laptop to be shipped somewhere other than their stated address — to a laptop farm, typically a house in the US run by a paid local facilitator, who plugs the machines in and installs remote access software. The worker then connects from China or North Korea through that machine, so the company sees a domestic IP.
US prosecutors have charged both sides of this. In one case, DOJ indicted two North Korean nationals along with facilitators in the US and Mexico; in another, two US nationals were sentenced for running farms that placed workers at more than a hundred US companies, generating over $5 million for the regime. One facilitator operated out of residences in Nashville.
The case everyone cites
In July 2024, the security-awareness company KnowBe4 published an unusually candid post explaining that it had hired one of these workers as a principal software engineer — and then caught him.
The candidate cleared four video interviews and a background check. The identity was a real US person's, stolen; the photo was a stock image modified with AI to match. Suspicious activity on the new hire's workstation was flagged on 15 July, and KnowBe4 says it cut off the account's restricted onboarding access within 25 minutes. Nothing was exfiltrated.
The reason this case matters is not that KnowBe4 was careless — it is that they were careful, and it still worked. Video interviews and a background check were not enough.
Where the Kim Jong Un question came from
At the RSA Conference in San Francisco on 28 April 2025, Adam Meyers, who runs counter-adversary operations at CrowdStrike, described his preferred screening question on a panel. His version was to ask how fat Kim Jong Un is.
Founders have reported the same thing independently. Harrison Leggio, who runs the crypto startup g8keep, told Fortune that roughly 95% of the résumés he receives come from North Korean engineers posing as Americans, and that asking an applicant to say something negative about Kim Jong Un usually makes them panic and block him. A widely-shared interview recording shows a candidate asked to repeat an insult, becoming visibly uncomfortable, claiming not to understand, and leaving the call.
It works — when it works — because insulting the leader is a criminal act in North Korea with consequences that extend to the speaker's family. It is not a bluff a loyal operative can comfortably call.
Why it is not a security control
Treat the question as a curiosity, not a gate. Four reasons:
- It is public. Meyers himself noted the adversary is adapting, and that FBI detection guidance is read in Pyongyang as well as in Virginia. A technique described on a conference stage in 2025 has had years to be trained against.
- Supervision varies. Workers based in China or Russia are not always under the same monitoring as those inside the DPRK, and reportedly do not always react.
- It produces false positives. Plenty of legitimate candidates will decline to insult a head of state on a recorded interview call, for perfectly ordinary reasons — professionalism, family in the region, or simple bewilderment.
- There is a person on the other end. Many of these workers are coerced: state-assigned, quota-bound, monitored, with relatives as collateral. The question is cheap for you and expensive for them.
Our position
We made a party game out of this because the premise is absurd and the regime deserves the mockery. We would rather you did not run it on real candidates. If you want the laugh, buy the deck and play it at the offsite.
What actually screens for this
The published guidance from Mandiant, Microsoft, and the US agencies converges on the same short list. None of it is exotic.
During hiring
- Verify identity against government ID with a liveness check, and confirm the person on the video call is the person on the document.
- Treat a résumé pairing a US address with a degree from a non-North-American university — Singapore, Japan, and Hong Kong recur — as worth a second look, not as proof of anything.
- Run profile photos through AI-image detection. Mandiant has repeatedly seen AI-modified headshots.
- Require camera on for interviews, and notice a candidate who will not.
- Confirm right to work with documents you actually inspect, and check references by calling the company, not the number on the résumé.
At onboarding
- Ship the laptop to the address on the employment record. Treat a change request as an exception requiring verification, because it is the single most reliable signal in the public record.
- Do a video-verified first-day handoff: the new hire, on camera, with the device.
- Alert on remote-access tooling appearing on a corporate endpoint — AnyDesk, TeamViewer, GoToMeeting and similar are recurring in these cases.
After hire
- Watch for impossible travel, VPN and residential-proxy exits, and logins whose working hours never match the stated time zone.
- Watch for one worker's device showing multiple concurrent sessions, or the account behaving like several people.
- Give new hires least privilege for a real probation window. KnowBe4's 25-minute containment only worked because the account was restricted.
If you think you have hired one
Do not confront them and do not just quietly terminate. Preserve the evidence, contain the account, and report it — in the US, to the FBI via ic3.gov and to your counsel. Paying a sanctioned party creates exposure under OFAC rules independent of any security impact, so legal needs to be in the room early.
Sources
- How a North Korean Fake IT Worker Tried to Infiltrate Us — KnowBe4, 23 July 2024.
- Staying a Step Ahead: Mitigating the DPRK IT Worker Threat — Mandiant / Google Cloud (UNC5267).
- Jasper Sleet: North Korean remote IT workers' evolving tactics — Microsoft Security, 30 June 2025.
- The one interview question that will protect you from North Korean fake workers — The Register, 29 April 2025 (Adam Meyers at RSAC).
- North Korean IT workers are spamming résumés; one founder asks them to insult Kim Jong Un — Fortune, 10 April 2025.
- Two North Korean Nationals and Three Facilitators Indicted — US Department of Justice.
- Two US Nationals Sentenced for Facilitating Fraudulent Remote IT Worker Scheme — US Department of Justice.
- How North Korean IT workers leverage AI and vulnerable Americans — CNN, 5 August 2025 (Treasury revenue figure).